Attackers are exploiting an authentication bypass vulnerability (CVE-2026-18577) in N-able N-central, a remote monitoring and management (RMM) solution…
Tag: Vulnerability
N‑able Patches Vulnerability Exploited to Hack N-central Servers
The N‑central vulnerability CVE-2026-18577 has been exploited in the wild after threat actors found a patch bypass.
KindaRails2Shell threatens Ruby on Rails apps (CVE-2026-66066)
A critical security vulnerability (CVE-2026-66066) in Ruby on Rails (aka Rails), one of the most widely used frameworks for building websites and web…
Critical N-able N-central Vulnerability Under Active Exploitation as Hotfix Lands
N-able has confirmed that a critical vulnerability in N-central, its flagship remote monitoring and management (RMM) platform, is being actively exploited…
Critical N-Able N-Central Vulnerability Allows Hackers to Gain god-mode Access to the RMM Console
N-able has disclosed a critical security vulnerability in its N-central remote monitoring and management (RMM) platform, which could allow unauthenticated…
Ruby on Rails Patches Critical Active Storage Vulnerability Affecting Image Processing
Ruby on Rails fixed a critical vulnerability that could let unauthenticated attackers read files and achieve remote code execution. Ruby on Rails has…
SonicWall SMA Zero-Days Let Attackers Turn One WebSocket Request Into Root Control
SonicWall SMA Secure Mobile Access appliances are again at the center of a zero-day storm, with chained flaws that let attackers turn a single crafted…
Estée Lauder Discloses HR Data Breach Linked to Oracle E-Business Suite Vulnerability
Estee Lauder announced that their Oracle E-Business Suite (EBS) system that manages human capital operations was targeted by cyber criminals who managed…
Adobe fixed a maximum-severity vulnerability flaw in Campaign Classic
Adobe fixed a maximum severity vulnerability in Campaign Classic that could let attackers run code remotely without user interaction. Adobe has addressed…
Ruby on Rails Patches Critical Vulnerability
The flaw can be exploited by unauthenticated attackers to read arbitrary files and potentially achieve remote code execution (RCE).
Autonomous AI Agent Exploits Zero-Day to Breach Hugging Face Infrastructure
An autonomous AI agent powered by OpenAI models breached Hugging Face’s production infrastructure in July 2026 after escaping its evaluation sandbox via a…
Chinese Hacker Uses DeepSeek AI to Orchestrate Vulnerability Exploits
A Chinese-speaking threat actor has been using DeepSeek’s AI models to orchestrate cyber-attacks targeting Asian organizations
Cisco FMC Zero-Day Actively Exploited, Static Credentials Could Expose Sensitive Data
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added a newly disclosed security flaw impacting Cisco Secure Firewall…
Keycloak Vulnerability Exposes User Names and Email Addresses Across Admin Boundaries
Keycloak has addressed a broken access control vulnerability that could allow restricted administrators to access usernames, email addresses, and other…
Vulnerability management needs an update for the AI era
Organizations must rethink long-held assumptions about patch management and change how they prioritize, remediate and manage cyber-risk, especially in…
CVE-2026-63077 TeamCity RCE Vulnerability
JetBrains has disclosed a critical authentication bypass vulnerability in TeamCity On-Premises that enables remote attackers to execute arbitrary…
Long-Lived Vulnerability in Microsoft Secure Boot
Microsoft’s Secure Boot has had a serious vulnerability for most of its existence. An industry-wide standard Microsoft invented to protect Windows, and…
Critical Code Execution Vulnerability Patched in TeamCity
Tracked as CVE-2026-63077, the security defect can be exploited without authentication via the agent polling protocol.
CosmosEscape Vulnerability Enables Full Takeover of Azure Cosmos DB Databases
A critical vulnerability chain in Azure Cosmos DB, named CosmosEscape, allowed attackers to gain full read and write access to every Cosmos DB database,…
FastJson RCE Zero-Day Actively Targets Organizations
Threat actors are actively exploiting the FastJson CVE-2026-16723 zero-day, with no patch available for affected FastJson 1.x versions.